---
tags:
- k8s
- l1
- flashcard-deck
- k8s-services
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Kubernetes Services & Ingress](../../../../library/portal/topics.md) | **Domain:** Kubernetes
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
k8s-services/052f9c3bc724	k8s-services	easy	k8s-services, loadbalancer, clusterip	How to create a service for an existing deployment called "alle" on port 8080 so the Pod(s) accessible via a Load Balancer?	The imperative way:\n\n`kubectl expose deployment alle --type=LoadBalancer --port 8080`\n\nExample: `kubectl expose deployment web --port=80 --target-port=8080 --type=ClusterIP`\n\nRemember: `--port`=Service port, `--target-port`=container port. Two distinct values.	projects/knowledge/interview/kubernetes/090-how-to-create-a-service-for-an-existing-deployment.txt
k8s-services/0b70c33828a0	k8s-services	easy	k8s-services, clusterip, nodeport	How to create a service that exposes a deployment?	kubectl expose deploy some-deployment --port=80 --target-port=8080\n\nExample: `kubectl expose deployment web --port=80 --target-port=8080 --type=ClusterIP`\n\nRemember: `--port`=Service port, `--target-port`=container port. Two distinct values.	projects/knowledge/interview/kubernetes/193-how-to-create-a-service-that-exposes-a-deployment.txt
k8s-services/0f16012c808b	k8s-services	easy	k8s-services, ingress, clusterip	How to list Ingress in your namespace?	`kubectl get ingress` lists all Ingress resources in the current namespace showing hosts, paths, and backends. Add `-o wide` for additional details like the ingress class and address. \nGotcha: Ingress requires an Ingress Controller (nginx, traefik, ALB) to be installed — without one, Ingress resources exist but do not route traffic.	projects/knowledge/interview/kubernetes/119-how-to-list-ingress-in-your-namespace.txt
k8s-services/0f4b1772d6e1	k8s-services	hard	k8s-services, dns, clusterip	How does Kubernetes handle DNS resolution for services and pods?	**DNS Resolution in Kubernetes:**\n* Pods are assigned a DNS name based on their name and namespace.\n* The internal DNS service in Kubernetes resolves these names to corresponding pod IP addresses.\n* Services also have DNS names based on their name and namespace, enabling easy service discovery.\n* Kubernetes has an internal DNS service that automatically assigns DNS names to pods and services. This allows for easy and dynamic DNS-based service discovery within the cluster.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/351-how-does-kubernetes-handle-dns-resolution-for-serv.txt
k8s-services/0ff9537f7315	k8s-services	easy	k8s-services, clusterip, nodeport	What is ClusterIP service type in Kubernetes?	ClusterIP is the default Kubernetes service that provides a service inside a cluster (with no external access) that other apps inside your cluster can access. It exposes the service on an internal IP in the cluster, making the service only reachable from within the cluster.\n\nRemember: ClusterIP = default, internal only. "Cluster Internal Protocol."\n\nUnder the hood: kube-proxy programs iptables/IPVS to load-balance to pods.	projects/knowledge/interview/kubernetes/400-what-is-clusterip.txt
k8s-services/10cc503f959d	k8s-services	medium	k8s-services, clusterip, nodeport, loadbalancer	What are the different services within Kubernetes?	Different types of Kubernetes services include:\n\n* ClusterIP service - Exposes the service on a cluster-internal IP\n* NodePort service - Exposes the service on each Node's IP at a static port\n* LoadBalancer service - Exposes the service externally using a cloud provider's load balancer\n* ExternalName service - Maps the service to the contents of the externalName field\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/399-what-are-the-different-services-within.txt
k8s-services/10e779410f93	k8s-services	medium	k8s-services, clusterip, nodeport	How readiness probe status affect Services when they are combined?	Only containers whose state set to Success will be able to receive requests sent to the Service.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/046-how-readiness-probe-status-affect-services-when-th.txt
k8s-services/11adcb673804	k8s-services	medium	k8s-services, ingress, clusterip	How to configure TLS with Ingress?	Add tls and secretName entries.\n\n```\nspec:\n  tls:\n  - hosts:\n    - some_app.com\n    secretName: someapp-secret-tls\n```\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/122-how-to-configure-tls-with-ingress.txt
k8s-services/12fc15a0deea	k8s-services	medium	k8s-services, clusterip, nodeport	How make an app accessible on private or external network?	Using a Kubernetes Service, which provides a stable virtual IP and DNS name that routes traffic to a set of pods matched by label selectors. Four types: ClusterIP (internal), NodePort (external via node ports), LoadBalancer (cloud LB), ExternalName (DNS alias). Services decouple consumers from individual pod IPs, which change on restart.	projects/knowledge/interview/kubernetes/081-how-make-an-app-accessible-on-private-or-external-.txt
k8s-services/19226050e8c9	k8s-services	medium	k8s-services, clusterip, nodeport	How would you map a service to an external address?	Use the ExternalName service type, which maps a service to an external DNS name (e.g., an RDS endpoint or external API). \nExample: `type: ExternalName` with `externalName: my.database.example.com`. This creates a CNAME record in cluster DNS. \nGotcha: ExternalName services do not proxy traffic — they only provide DNS resolution.	projects/knowledge/interview/kubernetes/105-how-would-you-map-a-service-to-an-external-address.txt
k8s-services/1a1c5aa23241	k8s-services	hard	k8s-services, endpoints, dns	Describe what happens when a container tries to connect with its corresponding Service for the first time. Explain who added each of the components you include in your description	- The container looks at the nameserver defined in /etc/resolv.conf\n  - The container queries the nameserver so the address is resolved to the Service IP\n  - Requests sent to the Service IP are forwarded with iptables rules (or other chosen software) to the endpoint(s).\n\nExplanation as to who added them:\n\n  - The nameserver in the container is added by kubelet during the scheduling of the Pod, by using kube-dns\n  - The DNS record of the service is added by kube-dns during the Service creation\n  - iptables rules are added by kube-proxy during Endpoint and Service creation	projects/knowledge/interview/kubernetes/109-describe-what-happens-when-a-container-tries-to-co.txt
k8s-services/22d889579504	k8s-services	medium	k8s-services, clusterip, nodeport	What are important steps in defining/adding a Service?	1. Making sure that targetPort of the Service is matching the containerPort of the Pod\n2. Making sure that selector matches at least one of the Pod's labels\n\nRemember: port=Service port, targetPort=container port, nodePort=external. Three distinct values.	projects/knowledge/interview/kubernetes/095-what-are-important-steps-in-definingadding-a-servi.txt
k8s-services/2503c9c96ae7	k8s-services	medium	k8s-services, clusterip, nodeport	After creating a service that forwards incoming external traffic to the containerized application, how to make sure it works?	You can run `curl <SERVICE IP>:<SERVICE PORT>` to examine the output.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/111-after-creating-a-service-that-forwards-incoming-ex.txt
k8s-services/26346ad80323	k8s-services	easy	k8s-services, clusterip, nodeport	What is a headless service?	A headless service is used to interface with service discovery mechanisms without being tied to a ClusterIP, therefore allowing you to directly reach pods without having to access them through a proxy. It is useful when neither load balancing nor a single Service IP is required. You create a headless service by setting clusterIP to None.\n\nRemember: Headless = ClusterIP:None. DNS returns pod IPs, not VIP. For StatefulSets.\n\nExample: `nslookup my-headless-svc` returns individual pod A records.	projects/knowledge/interview/kubernetes/407-what-is-a-headless-service.txt
k8s-services/2de590d166cb	k8s-services	easy	k8s-services, dns, clusterip	What is a Kubernetes Service and how does it enable networking?	Provides a stable IP address and DNS name for a set of pods.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/421-service.txt
k8s-services/2ebb79dc2b3f	k8s-services	easy	k8s-services, clusterip, nodeport	How to create a pod and a service with one command?	kubectl run nginx --image=nginx --restart=Never --port 80 --expose\n\nExample: `kubectl expose deployment web --port=80 --target-port=8080 --type=ClusterIP`\n\nRemember: `--port`=Service port, `--target-port`=container port. Two distinct values.	projects/knowledge/interview/kubernetes/194-how-to-create-a-pod-and-a-service-with-one-command.txt
k8s-services/2edb2be27feb	k8s-services	easy	k8s-services, clusterip, nodeport	What is the default service type in Kubernetes and what is it used for?	The default is ClusterIP and it's used for exposing a port internally. It's useful when you want to enable internal communication between Pods and prevent any external access.\n\nRemember: 4 types: ClusterIP, NodePort, LoadBalancer, ExternalName. Mnemonic: "CNLE."	projects/knowledge/interview/kubernetes/096-what-is-the-default-service-type-in-kubernetes-and.txt
k8s-services/3855b7a4befd	k8s-services	medium	k8s-services, clusterip, nodeport	True or False? the target port, in the case of running the following command, will be exposed only on one of the Kubernetes cluster nodes but it will routed to all the pods	False. It will be exposed on every node of the cluster and will be routed to one of the Pods (which belong to the ReplicaSet)\n\nExample: `kubectl expose deployment web --port=80 --target-port=8080 --type=ClusterIP`\n\nRemember: `--port`=Service port, `--target-port`=container port. Two distinct values.	projects/knowledge/interview/kubernetes/099-true-or-false-the-target-port-in-the-case-of-runni.txt
k8s-services/3d0576b97aac	k8s-services	hard	k8s-services, nodeport, ingress	Explain what will happen when running apply on the following block	It creates a new Service of the type "NodePort" which means it can be used for internal and external communication with the app. \nThe port of the application is 8080 and the requests will forwarded to this port. The exposed port is 2017. As a note, this is not a common practice, to specify the nodePort. \nThe port used TCP (instead of UDP) and this is also the default so you don't have to specify it. \nThe selector used by the Service to know to which Pods to forward the requests. In this case, Pods with the label "type: backend" and "service: some-app". 	projects/knowledge/interview/kubernetes/101-explain-what-will-happen-when-running-apply-on-the.txt
k8s-services/3edde90ec4b1	k8s-services	medium	k8s-services, clusterip, nodeport	How to get information on a certain service?	`kubectl describe service <SERVICE_NAME>`\n\nIt's more common to use `kubectl describe svc ...`\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/097-how-to-get-information-on-a-certain-service.txt
k8s-services/3fc48e84ebed	k8s-services	hard	k8s-services, ingress, clusterip	Discuss the concept of Ingress in Kubernetes.	* Ingress: Kubernetes resource that manages external access to services within the cluster.\n* Acts as an API object that defines how external HTTP/S traffic should be routed to services.\n* Supports features like path-based routing, SSL termination, and load balancing.\n* Ingress provides a flexible and configurable way to expose services to the external world. It allows for the definition of rules that govern how external requests are directed to different services within the cluster.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/325-discuss-the-concept-of-ingress-in-kubernetes.txt
k8s-services/4eb3bbf12eca	k8s-services	medium	k8s-services, ingress, network-policy	In case of two pods, if there is an egress policy on the source denining traffic and ingress policy on the destination that allows traffic then, traffic will be allowed or denied?	Denied. Both source and destination policies has to allow traffic for it to be allowed.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/165-in-case-of-two-pods-if-there-is-an-egress-policy-o.txt
k8s-services/4ee6f0fb3df5	k8s-services	medium	k8s-services, loadbalancer, clusterip	What is the LoadBalancer in Kubernetes?	The LoadBalancer service is used to expose services to the internet. A Network load balancer creates a single IP address that forwards all traffic to your service. It exposes the service externally using a cloud provider's load balancer.\n\nRemember: LoadBalancer = NodePort + cloud LB. Auto-provisions on cloud providers.\n\nGotcha: Bare-metal → stays Pending. Use MetalLB for on-prem.	projects/knowledge/interview/kubernetes/402-what-is-the-loadbalancer-in-kubernetes.txt
k8s-services/5964e105c577	k8s-services	medium	k8s-services, nodeport, loadbalancer	How to turn the following service into an external one?	Adding `type: LoadBalancer` and `nodePort`\n\n```\nspec:\n  selector:\n    app: some-app\n  type: LoadBalancer\n  ports:\n    - protocol: TCP\n      port: 8081\n      targetPort: 8081\n      nodePort: 32412\n```\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/102-how-to-turn-the-following-service-into-an-external.txt
k8s-services/5cc1e45cd708	k8s-services	medium	k8s-services, ingress, clusterip	What are some use cases for using Ingress?	* Multiple sub-domains (multiple host entries, each with its own service)\n* One domain with multiple services (multiple paths where each one is mapped to a different service/application)\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/118-what-are-some-use-cases-for-using-ingress.txt
k8s-services/66d0f0ffbfeb	k8s-services	easy	k8s-services, endpoints, clusterip	How to list the endpoints of a certain app?	`kubectl get ep <name>`\n\nUnder the hood: Endpoints object tracks matching pod IPs. No pods = empty Endpoints = no traffic.	projects/knowledge/interview/kubernetes/107-how-to-list-the-endpoints-of-a-certain-app.txt
k8s-services/6a44e08a7a10	k8s-services	medium	k8s-services, loadbalancer, ingress	An internal load balancer in Kubernetes is called ____ and an external load balancer is called ____	An internal load balancer in Kubernetes is called Service and an external load balancer is Ingress\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/112-an-internal-load-balancer-in-kubernetes-is-called-.txt
k8s-services/70f5030de7f8	k8s-services	medium	k8s-services, ingress, clusterip	Why using a wildcard in ingress host may lead to issues?	The reason you should not wildcard value in a host (like `- host: *`) is because you basically tell your Kubernetes cluster to forward all the traffic to the container where you used this ingress. This may cause the entire cluster to go down.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/116-why-using-a-wildcard-in-ingress-host-may-lead-to-i.txt
k8s-services/75ac8900ae75	k8s-services	medium	k8s-services, nodeport, clusterip	How to expose a ReplicaSet as a new service?	`kubectl expose rs <ReplicaSet Name> --name=<Service Name> --target-port=<Port to expose> --type=NodePort`\n\nFew notes:\n  - the target port depends on which port the app is using in the container\n  - type can be different and doesn't has to be specifically "NodePort"\n\nExample: `kubectl expose deployment web --port=80 --target-port=8080 --type=ClusterIP`\n\nRemember: `--port`=Service port, `--target-port`=container port. Two distinct values.	projects/knowledge/interview/kubernetes/141-how-to-expose-a-replicaset-as-a-new-service.txt
k8s-services/7b8af0e69029	k8s-services	medium	k8s-services, ingress, clusterip	Complete the following configuration file to make it Ingress	There are several ways to answer this question.\n\n```\napiVersion: networking.k8s.io/v1\nkind: Ingress\nmetadata:\n  name: someapp-ingress\nspec:\n  rules:\n  - host: my.host\n    http:\n      paths:\n      - path: /\n        pathType: Prefix\n        backend:\n          service:\n            name: someapp-internal-service\n            port:\n              number: 8080\n```\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/114-complete-the-following-configuration-file-to-make-.txt
k8s-services/7e010dfda431	k8s-services	easy	k8s-services, service-mesh, clusterip	What is a CNI (Container Networking Interface) in Kubernetes?	* CNI (Container Networking Interface): CNI is a standard for configuring network interfaces of container workloads.\n* It defines a set of APIs for network plugins to enable container communication.\n* CNI plugins facilitate the creation of network namespaces, IP addresses, routes, and iptables rules.\n* CNI provides a standardized way for container runtimes like Docker and containerd to interact with network plugins. These plugins enable the setup of networking resources for containers, allowing them to communicate with each other and external networks.	projects/knowledge/interview/kubernetes/349-what-is-a-cni-container-networking-interface-in-ku.txt
k8s-services/88f02cbd64f8	k8s-services	hard	k8s-services, clusterip, nodeport, loadbalancer	What Service types are there?	Four Kubernetes Service types: ClusterIP (internal-only, default), NodePort (exposes on each node's IP at a static port 30000-32767), LoadBalancer (provisions a cloud load balancer), and ExternalName (maps to an external DNS CNAME). Mnemonic: CNLE — ClusterIP, NodePort, LoadBalancer, ExternalName, ordered from most internal to most external.	projects/knowledge/interview/kubernetes/093-what-service-types-are-there.txt
k8s-services/88fa457d2103	k8s-services	medium	k8s-services, ingress, clusterip	What is Ingress Controller?	An implementation for Ingress. It's basically another pod (or set of pods) that does evaluates and processes Ingress rules and this it manages all the redirections. \n\nThere are multiple Ingress Controller implementations (the one from Kubernetes is Kubernetes Nginx Ingress Controller).\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/117-what-is-ingress-controller.txt
k8s-services/8d8eba984567	k8s-services	easy	k8s-services, clusterip, nodeport	What is a Service in Kubernetes?	An abstract way to expose an application running on a set of Pods as a network service. - read more [here](https://kubernetes.io/docs/concepts/services-networking/service)\n\nIn simpler words, it allows you to add an internal or external connectivity to a certain application running in a container.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/088-what-is-a-service-in-kubernetes.txt
k8s-services/917da1a4bba0	k8s-services	hard	k8s-services, loadbalancer, dns	How can you get a static IP for a Kubernetes load balancer?	A static IP for the Kubernetes load balancer can be achieved by changing DNS records since the Kubernetes Master can assign a new static IP address. You can also specify a loadBalancerIP in your service spec when using cloud providers that support it, or reserve a static IP through your cloud provider and then reference it in your service configuration.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/413-how-can-you-get-a-static-ip-for-a-kubernetes.txt
k8s-services/92f92e0a708b	k8s-services	medium	k8s-services, loadbalancer, clusterip	When would you use the "LoadBalancer" type	Mostly when you would like to combine it with cloud provider's load balancer\n\nRemember: LoadBalancer = NodePort + cloud LB. Auto-provisions on cloud providers.\n\nGotcha: Bare-metal → stays Pending. Use MetalLB for on-prem.	projects/knowledge/interview/kubernetes/104-when-would-you-use-the-loadbalancer-type.txt
k8s-services/95c6b2ca133b	k8s-services	medium	k8s-services, loadbalancer, ingress	What is the Ingress network, and how does it work?	An Ingress is an API object that allows users to access your Kubernetes services from outside the Kubernetes cluster. Users can configure the access by creating rules that define which inbound connections reach which services.\n\nHow it works: This is an API object that provides the routing rules to manage the external users' access to the services in the Kubernetes cluster through HTTPS/HTTP. With this, users can easily set up the rules for routing traffic without creating a bunch of load balancers or exposing each service to the nodes.	projects/knowledge/interview/kubernetes/403-what-is-the-ingress-network-and-how-does-it.txt
k8s-services/a1f9183428d1	k8s-services	easy	k8s-services, ingress, clusterip	What is an "Ingress"?	Manages external access to services, typically via HTTP.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/427-ingress.txt
k8s-services/a57e22827146	k8s-services	medium	k8s-services, nodeport, clusterip	What is NodePort service type in Kubernetes?	The NodePort service is the most fundamental way to get external traffic directly to your service. It opens a specific port on all Nodes and forwards any traffic sent to this port to the service. NodePort exposes the service on each Node's IP at a static port (the NodePort).\n\nRemember: NodePort: 30000-32767. "30K to 32K." Opens on ALL nodes.\n\nGotcha: NodePort on every node, even without target pods. Traffic forwarded internally.	projects/knowledge/interview/kubernetes/401-what-is-nodeport.txt
k8s-services/aff0fa7740d4	k8s-services	hard	k8s-services, loadbalancer, clusterip	Describe in high level what happens when you run kubectl expose deployment remo --type=LoadBalancer --port 8080	1. Kubectl sends a request to Kubernetes API to create a Service object\n2. Kubernetes asks the cloud provider (e.g. AWS, GCP, Azure) to provision a load balancer\n3. The newly created load balancer forwards incoming traffic to relevant worker node(s) which forwards the traffic to the relevant containers\n\nRemember: LoadBalancer = NodePort + cloud LB. Auto-provisions on cloud providers.\n\nGotcha: Bare-metal → stays Pending. Use MetalLB for on-prem.	projects/knowledge/interview/kubernetes/110-describe-in-high-level-what-happens-when-you-run-k.txt
k8s-services/b7104fee5df0	k8s-services	hard	k8s-services, endpoints, dns	Describe in detail what happens when you create a service	1. Kubectl sends a request to the API server to create a Service\n2. The controller detects there is a new Service\n3. Endpoint objects created with the same name as the service, by the controller\n4. The controller is using the Service selector to identify the endpoints\n5. kube-proxy detects there is a new endpoint object + new service and adds iptables rules to capture traffic to the Service port and redirect it to endpoints\n6. kube-dns detects there is a new Service and adds the container record to the dns server	projects/knowledge/interview/kubernetes/106-describe-in-detail-what-happens-when-you-create-a-.txt
k8s-services/bbe50188016e	k8s-services	medium	k8s-services, endpoints, clusterip	How to verify that a certain service configured to forward the requests to a given pod	Run `kubectl describe service` and see if the IPs from "Endpoints" match any IPs from the output of `kubectl get pod -o wide`\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/100-how-to-verify-that-a-certain-service-configured-to.txt
k8s-services/bc7af66e37ed	k8s-services	medium	k8s-services, ingress, clusterip	What is Ingress Default Backend?	It specifies what do with an incoming request to the Kubernetes cluster that isn't mapped to any backend (= no rule to for mapping the request to a service). If the default backend service isn't defined, it's recommended to define so users still see some kind of message instead of nothing or unclear error.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/120-what-is-ingress-default-backend.txt
k8s-services/c2434a943f00	k8s-services	hard	k8s-services, clusterip, nodeport, loadbalancer	Explain the differences between ClusterIP, NodePort, and LoadBalancer service types.	**Service Types in Kubernetes:**\n • ClusterIP:\n • Exposes the service on an internal IP within the cluster.\n • Suitable for intra-cluster communication.\n • NodePort:\n • Exposes the service on a static port on each node's IP.\n • Makes the service accessible externally.\n • LoadBalancer:\n • Requests an external load balancer to manage the service.\n • Useful for exposing services externally in cloud environments. \nDifferent service types provide varying levels of accessibility. projects/knowledge/interview/kubernetes/350-explain-the-differences-between-clusterip-nodeport.txt\n\nRemember: ClusterIP = default, internal only. "Cluster Internal Protocol."\n\nUnder the hood: kube-proxy programs iptables/IPVS to load-balance to pods.	
k8s-services/c4bde1891709	k8s-services	hard	k8s-services, clusterip, ingress	Explain the meaning of "http", "host" and "backend" directives	host is the entry point of the cluster so basically a valid domain address that maps to cluster's node IP address \nthe http line used for specifying that incoming requests will be forwarded to the internal service using http. \nbackend is referencing the internal service (serviceName is the name under metadata and servicePort is the port under the ports section).\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/115-explain-the-meaning-of-http-host-and-backend-direc.txt
k8s-services/d20669044d0c	k8s-services	hard	k8s-services, ingress, clusterip	How to configure a default backend?	Create Service resource that specifies the name of the default backend as reflected in `kubectl describe ingress ...` and the port under the ports section.\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/121-how-to-configure-a-default-backend.txt
k8s-services/d383e94cd622	k8s-services	hard	k8s-services, clusterip, service-mesh	Why is conntrack critical in Kubernetes?	Conntrack (connection tracking) is essential for Kubernetes service networking:\n\n**How services work**:\n* ClusterIP services use iptables/IPVS for load balancing\n* Every connection to a service gets NAT'd to a pod\n* Conntrack tracks these NAT translations\n\n**Why it matters**:\n* Without conntrack, return packets can't find their way back\n* Every active connection uses a conntrack entry\n* Table has fixed size (default often 65536 or 131072)\n\n**Failure mode**:\n* Table fills up → new connections fail\n* Packets dropped silently\n* Affects ENTIRE cluster, not just one service\n\\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/379-why-is-conntrack-critical-in-kubernetes.txt
k8s-services/ecdd525eeeb5	k8s-services	medium	k8s-services, ingress, clusterip	What is a Kubernetes Ingress resource and how does it route external traffic?	From Kubernetes docs: "Ingress exposes HTTP and HTTPS routes from outside the cluster to services within the cluster. Traffic routing is controlled by rules defined on the Ingress resource."\n\nRead more [here](https://kubernetes.io/docs/concepts/services-networking/ingress/)\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/113-what-is-ingress.txt
k8s-services/ee1e31505c68	k8s-services	easy	k8s-services, clusterip, nodeport	What's the default Service type?	ClusterIP is the default Service type, providing an internal-only virtual IP accessible only within the cluster. Used for service-to-service communication (e.g., frontend pods talking to backend pods). Access it by service name via cluster DNS: `http://my-service.my-namespace.svc.cluster.local`. To expose externally, use NodePort or LoadBalancer instead.	projects/knowledge/interview/kubernetes/092-whats-the-default-service-type.txt
k8s-services/f9f43ef230d4	k8s-services	medium	k8s-services, ingress, clusterip	What would you use to route traffic from outside the Kubernetes cluster to services within a cluster?	Ingress. It exposes HTTP/HTTPS routes to services inside the cluster, with support for host/path-based routing, TLS termination, and load balancing — managed by an Ingress Controller (nginx, traefik, etc.).\n\nRemember: Services use label selectors to find pods. Change labels→change which pods get traffic.	projects/knowledge/interview/kubernetes/103-what-would-you-use-to-route-traffic-from-outside-t.txt
k8s-services/fcb62048a683	k8s-services	hard	k8s-services, clusterip, nodeport, loadbalancer	Explain the different Service types in Kubernetes and when to use each.	Kubernetes Services expose Pods to network traffic. Four types exist:\n\n1. ClusterIP (default):\n   - Internal cluster IP only\n   - Not accessible from outside\n   - Use: Internal microservice communication\n\n2. NodePort:\n   - Exposes service on each node's IP at a static port (30000-32767)\n   - Accessible from outside via <NodeIP>:<NodePort>\n   - Use: Development, simple external access\n\n3. LoadBalancer:\n   - Creates external load balancer (cloud provider)\n   - Automatically creates NodePort and ClusterIP\n   - Use: Production external access in cloud environments\n\n4.\n\nRemember: 4 types: ClusterIP, NodePort, LoadBalancer, ExternalName. Mnemonic: "CNLE."	projects/knowledge/interview/kubernetes/454-service-types.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Kubernetes Services & Ingress](../../../../library/topics/k8s-services-and-ingress/index.md) (Topic Pack, L1) — Kubernetes Services & Ingress
- [Runbook: Ingress 502 Bad Gateway](../../../../library/runbooks/kubernetes/ingress-502.md) (Runbook, L2) — Kubernetes Services & Ingress

<!-- wiki:related:end -->
